Skip to content

fix(font): bound CFF indices and dictionary operands - #1058

Merged
andiwand merged 2 commits into
mainfrom
review/40-cff-parser-bounds
Oct 5, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/40-cff-parser-bounds

Conversation

@andiwand

@andiwand andiwand commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

CFF INDEX iteration could wrap at 65,535 entries, offsets could wrap or point outside the font, and dictionary/glyph reads could consume bytes from the next structure. Bound each view and validate ranges before expansion or integer conversion. Real operands use the shared locale-independent number parser. A quirk that only affects one glyph or operand does not refuse the font: an unreadable real reads as zero, a charset range past the glyphs is clipped, and FDSelect ranges out of order or with an unknown FD fall back to the Top DICT widths.

Validation: all 50 PDF corpus cases pass, alongside the font and Type1 suites. The corpus logs retain a missing-glyph font substitution and cross-reference recovery warning. Four focused regressions cover maximum INDEX counts, invalid ranges/operands, German numeric locale, and FDSelect coverage. Bounds follow Adobe CFF sections 4, 5, 13 and 19.

@andiwand
andiwand force-pushed the review/39-sfnt-serialization branch from 8bb6c57 to 53fde49 Compare October 5, 2026 11:31
Base automatically changed from review/39-sfnt-serialization to main October 5, 2026 11:50
andiwand and others added 2 commits October 5, 2026 13:57
A PDF falls back to a substitute font when its embedded font is refused,
so the page shows the wrong glyphs. These quirks now pass, as before this
change: an INDEX whose first offset is not one, an unreadable real (it
reads as zero), a reserved nibble, trailing DICT operands, a charset range
past the glyphs (clipped), and FDSelect ranges that are out of order, past
the glyphs or name an unknown FD (widths_for_glyph falls back). The bounds
of INDEX, DICT and charstring reads stay strict.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand force-pushed the review/40-cff-parser-bounds branch from f1911e3 to 7eedf8d Compare October 5, 2026 12:02
@andiwand
andiwand merged commit 142b187 into main Oct 5, 2026
23 checks passed
@andiwand
andiwand deleted the review/40-cff-parser-bounds branch October 5, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant